fix: Re-introduce event fetch backoff #2201

Merged
nex merged 8 commits from nex/fix/state-fetch-backoff into main 2026-09-01 16:24:18 +00:00
Owner

Some prior versions of continuwuity (I forget when it was removed) had a per-event backoff system that prevented the server constantly asking for the same events it's never going to see. This was removed at some point, likely in #1818, which now means continuwuity does not attempt to slow down when asking for events it isn't allowed to get, resulting in #2090. As I run several servers behind the same reverse proxy that happen to be backfill candidates, I have seen my request rate surge from 20 rps average to 100 rps average, which obviously isn't great.

This PR re-introduces backoff on event fetches using the same algorithm as federation transaction sending.

Fixes: #2090

Pull request checklist:

  • This pull request targets the main branch, and the branch is named something other than
    main.
  • I have written an appropriate pull request title and my description is clear.
  • I understand I am responsible for the contents of this pull request.
  • I have followed the contributing guidelines:
Some prior versions of continuwuity (I forget when it was removed) had a per-event backoff system that prevented the server constantly asking for the same events it's never going to see. This was removed at some point, likely in #1818, which now means continuwuity does not attempt to slow down when asking for events it isn't allowed to get, resulting in #2090. As I run several servers behind the same reverse proxy that happen to be backfill candidates, I have seen my request rate surge from 20 rps average to 100 rps average, which obviously isn't great. This PR re-introduces backoff on event fetches using the same algorithm as federation transaction sending. Fixes: #2090 <!-- Example: This pull request allows us to warp through time and space ten times faster than before by double-inverting the warp drive with hyperheated jump fluid, both making the drive faster and more efficient. This resolves the common issue where we have to wait more than 10 milliseconds to engage, use, and disengage the warp drive when travelling between galaxies. --> <!-- Closes: #... --> <!-- Fixes: #... --> <!-- Uncomment the above line(s) if your pull request fixes an issue or closes another pull request by superseding it. Replace `#...` with the issue/pr number, such as `#123`. --> **Pull request checklist:** <!-- You need to complete these before your PR can be considered. If you aren't sure about some, feel free to ask for clarification in #dev:continuwuity.org. --> - [x] This pull request targets the `main` branch, and the branch is named something other than `main`. - [x] I have written an appropriate pull request title and my description is clear. - [x] I understand I am responsible for the contents of this pull request. - I have followed the [contributing guidelines][c1]: - [x] My contribution follows the [code style][c2], if applicable. - [x] I ran [pre-commit checks][c1pc] before opening/drafting this pull request. - [ ] I have [tested my contribution][c1t] (or proof-read it for documentation-only changes) myself, if applicable. This includes ensuring code compiles. - [x] My commit messages follow the [commit message format][c1cm] and are descriptive. <!-- Notes on these requirements: - While not required, we encourage you to sign your commits with GPG or SSH to attest the authenticity of your changes. - While we allow LLM-assisted contributions, we do not appreciate contributions that are low quality, which is typical of machine-generated contributions that have not had a lot of love and care from a human. Please do not open a PR if all you have done is asked ChatGPT to tidy up the codebase with a +-100,000 diff. - In the case of code style violations, reviewers may leave review comments/change requests indicating what the ideal change would look like. For example, a reviewer may suggest you lower a log level, or use `match` instead of `if/else` etc. - In the case of code style violations, pre-commit check failures, minor things like typos/spelling errors, and in some cases commit format violations, reviewers may modify your branch directly, typically by making changes and adding a commit. Particularly in the latter case, a reviewer may rebase your commits to squash "spammy" ones (like "fix", "fix", "actually fix"), and reword commit messages that don't satisfy the format. - Pull requests MUST pass the `Checks` CI workflows to be capable of being merged. This can only be bypassed in exceptional circumstances. If your CI flakes, let us know in matrix:r/dev:continuwuity.org. - Pull requests have to be based on the latest `main` commit before being merged. If the main branch changes while you're making your changes, you should make sure you rebase on main before opening a PR. Your branch will be rebased on main before it is merged if it has fallen behind. - We typically only do fast-forward merges, so your entire commit log will be included. Once in main, it's difficult to get out cleanly, so put on your best dress, smile for the cameras! --> [c1]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md [c2]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/docs/development/code_style.mdx [c1pc]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#pre-commit-checks [c1t]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#running-tests-locally [c1cm]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#commit-messages
nex self-assigned this 2026-08-28 15:00:38 +00:00
style: Remove unused import and reformat
Some checks failed
Auto Labeler / Apply labels based on changed files (pull_request_target) Successful in 4s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m17s
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m28s
Checks / Changelog / Check changelog is added (pull_request_target) Failing after 7s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
84b974579e
nex force-pushed nex/fix/state-fetch-backoff from 84b974579e
Some checks failed
Auto Labeler / Apply labels based on changed files (pull_request_target) Successful in 4s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m17s
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m28s
Checks / Changelog / Check changelog is added (pull_request_target) Failing after 7s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 6e30efb64f
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 13s
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
Update flake hashes / update-flake-hashes (pull_request) Has been cancelled
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
2026-08-28 15:08:05 +00:00
Compare
nex force-pushed nex/fix/state-fetch-backoff from 6e30efb64f
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 13s
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
Update flake hashes / update-flake-hashes (pull_request) Has been cancelled
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
to 6cfbb41a42
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 8s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m22s
Checks / Prek / Check changed files (pull_request) Successful in 7s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m27s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m31s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 12m14s
2026-08-28 15:08:34 +00:00
Compare
nex requested review from Owners 2026-08-28 15:17:01 +00:00
@ -485,3 +475,2 @@
}
debug!(elapsed=?start.elapsed(),"Fetching {target_id} over federation");
self.ensure_can_pull_event(&target_id).inspect_err(|e| {
Author
Owner

Not sure if this warrants a comment explicitly calling it out, but failing the entire fetch routine immediately here is deliberate - from my logs, it looks like the 5 retry attempts are generally wasted, and errors are usually final (e.g. 403), meaning we ended up sending 5 requests per failed event to every backfill remote, exponentially.

If we can't pull a missing auth event at any point, it is impossible for us to safely continue. The old backoff system simply dropped events which couldn't be fetched, which would lead to incorrect behaviour on pdu check 4. If we can't fetch auth events, we can't auth the event, even if only one is missing.

As for why it doesn't matter for prev events - if we are missing some prev events, we won't be able to calculate the state before the incoming event locally, and will fall back to asking the remote server for the state/_ids. From there, we either get the whole state, or atomically fetch using fetch_and_handle_auth_events, meaning we always have all events necessary to calculate PDU check 5 (unless, of course, FAHAE fails to fetch an event, bailing out the entire thing yet again)

Not sure if this warrants a comment explicitly calling it out, but failing the entire fetch routine immediately here is deliberate - from my logs, it looks like the 5 retry attempts are generally wasted, and errors are usually final (e.g. 403), meaning we ended up sending 5 requests per failed event to every backfill remote, exponentially. If we can't pull a missing auth event at any point, it is impossible for us to safely continue. The old backoff system simply dropped events which couldn't be fetched, which would lead to incorrect behaviour on pdu check 4. If we can't fetch auth events, we can't auth the event, even if only one is missing. As for why it doesn't matter for *prev* events - if we are missing some prev events, we won't be able to calculate the state before the incoming event locally, and will fall back to asking the remote server for the state/_ids. From there, we either get the whole state, or atomically fetch using `fetch_and_handle_auth_events`, meaning we always have all events necessary to calculate PDU check 5 (unless, of course, FAHAE fails to fetch an event, bailing out the entire thing yet again)
fix: Don't increment backoff if we're still in backoff
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 14s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m23s
Checks / Prek / Check changed files (pull_request) Successful in 8s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m26s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m8s
ffff986763
eleboucher requested changes 2026-08-28 16:04:28 +00:00
Dismissed
@ -664,3 +667,1 @@
} else {
Some(event_id.to_owned())
}
(discovered_events.contains_key(event_id)
Contributor

This is inverted. missing_prev now collects the events we already have.

This is inverted. missing_prev now collects the events we already have.
Author
Owner

I've got a knack for doing this

I've got a knack for doing this
nex marked this conversation as resolved
fix: Re-invert prev events filter in fetch_prev_events
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m16s
Checks / Prek / Check changed files (pull_request) Successful in 7s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m18s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m1s
36abe7ba66
eleboucher approved these changes 2026-08-29 14:23:03 +00:00
ginger approved these changes 2026-09-01 16:13:17 +00:00
nex merged commit 03d669594e into main 2026-09-01 16:24:18 +00:00
nex deleted branch nex/fix/state-fetch-backoff 2026-09-01 16:24:18 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
continuwuation/continuwuity!2201
No description provided.